Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementHard
A cybersecurity consultant is advising a startup on its risk management strategy. The startup has limited resources and needs to prioritize its security efforts. The consultant recommends focusing on risks that have both a high likelihood of occurring and a high impact if they do occur, before addressing risks with lower likelihood or impact. This approach is fundamental to which risk management concept?
- ARisk Reporting
- BRisk Prioritization
- CRisk Appetite
- DRisk Categorization
Show answer & explanationAnswer & explanation
Correct answer: B. Risk Prioritization
Prioritizing risks based on a combination of their likelihood and impact to determine which ones to address first is a core aspect of risk prioritization. This allows organizations to allocate limited resources effectively.
Why the other options are wrong
- A. Risk reporting is the communication of risk information, not the act of ranking them.
- C. Risk appetite is the level of risk the organization is willing to accept, which informs prioritization but isn't the act of prioritization itself.
- D. Risk categorization involves grouping similar risks, but not necessarily ranking them for action.
Risk Prioritization
The process of ranking identified risks based on their assessed likelihood and impact, to determine which risks require the most immediate attention and resource allocation.
- Crucial for effective resource allocation.
- Often uses a risk matrix (likelihood vs. impact).
- Ensures high-severity and high-probability risks are addressed first.
Memory trick: Likelihood and Impact create the priority list.